guide (Updated: 2026-09-22)

Netcup Free Hardware Network Firewall Guide: 500 Stateful Rules & IPv6 ND Pitfalls

Netcup G12 servers include complimentary datacenter-grade stateful firewalls. Complete operational guide on SCP rule provisioning, crucial ICMPv6 Neighbor Discovery configuration, Cloudflare IP automation, lockout rescue, and dual-layer Fail2ban defense.

#Network Firewall #SCP Panel #Security Hardening #ICMPv6 #SSH Security #Fail2ban #G12 Cloud

In traditional cloud hosting, developers rely predominantly on guest OS-level firewalls such as ufw, iptables, or nftables.

However, software-based firewalls have a major architectural vulnerability: during heavy volumetric port scanning or SYN flood attacks, malicious traffic traverses the physical switch, floods the virtual NIC queue, and exhausts the hypervisor’s CPU soft-interrupt (SoftIRQ) cycles, causing latency spikes or service degradation.

To solve this, Netcup equips all Generation 12 (G12) servers (including x86 VPS, ARM, and Root Servers) with a complimentary, enterprise-grade stateful hardware firewall running directly on datacenter top-of-rack switches.

Here is a complete operational blueprint for configuring rules, avoiding the fatal ICMPv6 lockout, and integrating automated defense scripts.


1. Hardware Edge Firewall vs. Guest OS Firewalls

Firewall Layer Comparison
STATEFUL PACKET INSPECTION
Guest OS Firewall (UFW / iptables) OS Level
  • ✕ Malicious packets must penetrate the network stack and reach the kernel.
  • ✕ Heavy port scans generate excessive kernel soft-interrupts.
  • ✕ Misconfiguration can freeze the network stack completely.
Netcup Datacenter Switch Firewall Hardware ACL
  • ✓ Dropped before reaching the host: 0% CPU & RAM overhead.
  • ✓ Stateful tracking: Outbound requests allow return traffic automatically.
  • ✓ 500 active rules quota with discrete and range port support.

2. Production-Grade Inbound Rule Blueprint

The golden security principle: Default DROP on all inbound traffic, explicitly allow strictly necessary ports.

Configure rules in SCP sequentially from top to bottom:

PriorityDirectionProtocolSource CIDRPort RangeActionEssential Purpose & Caveats
1InboundTCPYour.Static.IP/3222 (or custom SSH)ACCEPTRestrict administrative SSH exclusively to trusted IPs
2InboundTCP0.0.0.0/0 & ::/080ACCEPTPublic HTTP (required for ACME Let’s Encrypt validation)
3InboundTCP0.0.0.0/0 & ::/0443ACCEPTPublic HTTPS secure traffic
4InboundICMP0.0.0.0/0AnyACCEPTIPv4 Ping diagnostics and path MTU discovery
5 (Crucial)InboundICMPv6::/0AnyACCEPT🔥 MANDATORY: IPv6 Neighbor Discovery Protocol (NDP)
6 (Catch-all)InboundALL0.0.0.0/0 & ::/0AnyDROPBlock all unlisted ports at the datacenter switch

[!CAUTION]

Deep Dive: The Critical ICMPv6 Neighbor Discovery Trap

Unlike IPv4 (which relies on ARP broadcast), IPv6 uses ICMPv6 Neighbor Solicitation (NS) and Neighbor Advertisement (NA) to resolve link-layer addresses. Netcup’s upstream gateway periodically probes your virtual interface with ICMPv6 NS packets. If you drop ICMPv6, your server cannot answer gateway probes, causing the gateway to flush your IP from its neighbor cache and rendering your IPv6 offline within minutes!


3. Step-by-Step SCP Provisioning

  1. Log into the Netcup Server Control Panel (SCP).
  2. Select your instance (v220xxxxxxxx) from the left-hand navigation.
  3. Click the Network tab in the top navigation bar.
  4. Select the Firewall sub-tab.
  5. If inactive, click the green button Activate Firewall (Firewall aktivieren).
  6. Click Add rule to input each entry:
    • Direction: Inbound
    • Protocol: TCP, UDP, ICMP, or ICMPv6
    • Source IP / Subnet: Standard CIDR format (e.g. 1.2.3.4/32, 0.0.0.0/0, ::/0)
    • Port / Range: Single (22), comma-separated (80,443), or span (8000-8080)
    • Action: ACCEPT or DROP
  7. Click Save changes. Rules propagate to physical switches within 15 seconds.

4. Emergency Lockout Recovery

If you mistakenly lock yourself out of SSH:

Option A: HTML5 VNC Console (Bypasses Network Firewall)

  1. Go to SCP -> Screen.
  2. Launch the HTML5 VNC Viewer.
  3. Because VNC interfaces directly with KVM’s virtual display hardware, it is 100% immune to firewall blocks. Log in as root to diagnose.

Option B: Deactivate Firewall via SCP

  1. In SCP -> Network -> Firewall, click the red Deactivate Firewall button.
  2. The switch immediately stops filtering, restoring your SSH access instantly so you can correct your whitelist rule.

5. Dual-Layer Defense: Hardware Firewall + Local Fail2ban

While the datacenter firewall stops port scans, legitimate HTTP/HTTPS ports (80/443) require local Layer-7 protection against brute-force and web probing:

# Install Fail2ban on Debian 12 / Ubuntu 24.04
apt update && apt install fail2ban -y

Configure /etc/fail2ban/jail.local:

[DEFAULT]
bantime = 3600
findtime = 600
maxretry = 5
banaction = nftables-multiport

[sshd]
enabled = true
port = 22

[nginx-botsearch]
enabled = true
port = http,https
logpath = /var/log/nginx/access.log
maxretry = 2

Restart Fail2ban:

systemctl restart fail2ban
fail2ban-client status sshd

With this architecture, the datacenter switch drops unauthorized traffic with zero CPU hit, while Fail2ban dynamically neutralizes application-layer attacks.

❓Frequently Asked Questions (FAQ)

Is the Netcup hardware firewall completely free of charge?▼
Yes, 100% free! The firewall operates directly at Netcup's top-of-rack (ToR) switch layer and is complimentary across all Generation 12 VPS, ARM, and Root Server instances. Each public network interface supports up to 500 stateful filtering rules.
Why does my IPv6 connection drop completely after setting a default DROP rule?▼
This is a classic trap: IPv6 relies strictly on ICMPv6 for Neighbor Discovery Protocol (NDP) and Router Advertisements (RA). If your firewall drops inbound ICMPv6 without an explicit ACCEPT rule for ::/0, the datacenter gateway cannot resolve your MAC address, severing your IPv6 routing within 5-10 minutes.
What should I do if I lock myself out of SSH?▼
You have two instant recovery methods: 1) Open the HTML5 VNC console in SCP -> Screen (which communicates over the hypervisor's internal video bus and bypasses the network firewall entirely); or 2) In SCP -> Network -> Firewall, click the red 'Deactivate Firewall' button to temporarily unblock all ports.
Do I still need local iptables/UFW or Fail2ban inside Linux?▼
Yes, strongly recommended! The datacenter switch firewall acts as your first coarse filter, dropping unauthorized port scans and SYN floods before they reach your virtual NIC. Local Fail2ban/nftables acts as your second layer, inspecting application logs on open ports (e.g. 80/443) and mitigating brute-force and Layer-7 attacks.